Pluck

Vendor:

First CVE: Feb 24, 2009 · Active for 17 years

43
Total CVEs
More Total CVEs than 97% of tracked products
3.9
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
7.3
Avg CVSS
Higher Avg CVSS than 46% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pluck over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 24, 2009
17 years ago
Most Recent CVE
Jul 23, 2025
366 days ago

CVE Severity & Scoring

Pluck43 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network39 (90.7%)
Unknown4 (9.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low37 (86.0%)
High2 (4.7%)
Unknown4 (9.3%)
User Interaction
None22 (51.2%)
Unknown4 (9.3%)
Required17 (39.5%)
Privileges Required
Low6 (14.0%)
High11 (25.6%)
None22 (51.2%)
Unknown4 (9.3%)

Top CVEs

Signals from CVEs in this product scope (43 CVEs).

43 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A file upload restriction bypass vulnerability in Pluck CMS before 4.7.13 allows an admin privileged user to gain access in the host through the "manage files" functionality, which
Dec 16, 20207.255NOYES
In Pluck 4.7.16, an admin user can use the theme upload functionality at /admin.php?action=themeinstall to perform remote code execution.
Mar 18, 20227.247NOYES
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a
Jun 5, 20189.843NOYES
An arbitrary file upload vulnerability in the component /inc/modules_install.php of Pluck-CMS v4.7.18 allows attackers to execute arbitrary code via uploading a crafted ZIP file.
Dec 14, 20238.837NONO
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot
May 22, 20096.833NOYES
File Upload vulnerability in PluckCMS v.4.7.10 allows a remote attacker to execute arbitrary code via the trashcan_restoreitem.php file.
Jun 20, 20237.232NOYES
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
Mar 17, 20179.832NONO
data/inc/files.php in Pluck 4.7.8 allows remote attackers to execute arbitrary code by uploading a .htaccess file that specifies SetHandler x-httpd-php for a .txt file, because onl
Apr 19, 20199.831NONO
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allows remote attackers to include and execute arbitrary local fi
Feb 24, 20096.831NOYES
Zip Slip vulnerability in Pluck-CMS Pluck 4.7.15 allows an attacker to upload specially crafted zip files, resulting in directory traversal and potentially arbitrary code execution
Dec 10, 20219.830NONO

Exploit Exposure

Signals from CVEs in this product scope (43 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
16.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (43 CVEs).

Media Mentions

Signals from CVEs in this product scope (43 CVEs).

Top CNAs Publishing CVEs For Pluck

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.7.977.30.9%00
4.7.819.83.6%00
4.7.747.32.6%01
4.7.2017.20.5%00
4.7.236.81.6%00
4.7.1838.010.1%00
4.7.1646.63.6%01
4.7.1567.61.3%00
4.7.1118.83.5%00
4.7.1067.42.8%01
4.716.80.7%00
4.6.216.815.0%01
4.6.116.81.9%01
4.5.316.85.0%01